DAPSSADAPSSA

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

By DAPSSA AI Desk | 2026-06-29T07:12:11.204Z
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Overview

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain 'compatible' with npm v12's security hardenings," JFrog said in a

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html

Join the Discussion